SUSE-SU-2026:2830-1
Vulnerability Summary
Timeline
Description
Security update for warewulf4 This update for warewulf4 fixes the following issues: Update to v4.7.0. Security issues fixed: - CVE-2025-69725: incorrect input validation in the `RedirectSlashes` function can lead to an open redirect (bsc#1258511). - CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad `SETTINGS_MAX_FRAME_SIZE` can lead to a denial of service (bsc#1265653). - CVE-2026-34986: github.com/go-jose/go-jose/v4: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262810). - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266483). Other updates and bugfixes: - Add correct flag `--update-overlays` fix (bsc#1268790). - v4.7.0: * New `wwctl` unset command * Refactored server routes (URLs) * New `/files/` route for serving individual files and templates * Server TLS support * Removed support for fetching individual overlays and individual files from overlays * Fixed whitespace handling around template functions * Security fixes, including updated Go and library versions - v4.6.5: * New wwctl overlay info command * Fixed `wwctl` image import `--update` option * Cross-arch support for `wwclient` * Improved IPv6 support * Improved support for bonded interfaces * Renamed `debian.interfaces` overlay to `ifupdown` * New `systemd-networkd` overlay * `warewulf-dracut` fixes, including `provision-to-disk` fixes - Remove `slurm-overlay` package. - Fix `wwctl` image import `--update` option (bsc#1254470).
Affected Systems
- suse•warewulf4&distro=SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
< 4.7.0-150500.6.42.1
- suse•warewulf4&distro=SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
< 4.7.0-150500.6.42.1
- suse•warewulf4&distro=SUSE Linux Enterprise Module for HPC 15 SP7
< 4.7.0-150500.6.42.1
- suse•warewulf4&distro=SUSE Linux Enterprise Server 15 SP6-LTSS
< 4.7.0-150500.6.42.1
References (11)
- https://www.suse.com/support/update/announcement/2026/suse-su-20262830-1/
- https://bugzilla.suse.com/1254470
- https://bugzilla.suse.com/1258511
- https://bugzilla.suse.com/1262810
- https://bugzilla.suse.com/1265653
- https://bugzilla.suse.com/1266483
- https://bugzilla.suse.com/1268790
- https://www.suse.com/security/cve/CVE-2025-69725
- https://www.suse.com/security/cve/CVE-2026-33814
- https://www.suse.com/security/cve/CVE-2026-34986
- https://www.suse.com/security/cve/CVE-2026-39821